58
1
2
3
4
(4) by inserting after section 227, as so redesignated, the following:
‘‘SEC. 228. CYBERSECURITY PLANS.
‘‘(a) DEFINITIONS.—In this section—
5
‘‘(1) the term ‘agency information system’
6
means an information system used or operated by an
7
agency or by another entity on behalf of an agency;
8
‘‘(2) the terms ‘cybersecurity risk’ and ‘infor-
9
mation system’ have the meanings given those terms
10
in section 227;
11
‘‘(3) the term ‘intelligence community’ has the
12
meaning given the term in section 3(4) of the Na-
13
tional Security Act of 1947 (50 U.S.C. 3003(4));
14
and
15
‘‘(4) the term ‘national security system’ has the
16
meaning given the term in section 11103 of title 40,
17
United States Code.
18
‘‘(b) INTRUSION ASSESSMENT PLAN.—
19
‘‘(1) REQUIREMENT.—The Secretary, in coordi-
20
nation with the Director of the Office of Manage-
21
ment and Budget, shall develop and implement an
22
intrusion assessment plan to identify and remove in-
23
truders in agency information systems.
24
‘‘(2) EXCEPTION.—The intrusion assessment
25
plan required under paragraph (1) shall not apply to
† S 754 ES